OpenAI offers Zero Data Retention and Private Safety Processing for enterprise API customers

·

OpenAI said Tuesday it will offer Zero Data Retention for eligible API customers using its frontier models, alongside a preview of a new system meant to preserve safety monitoring without exposing customer content to the company’s staff.

The Aug. 19 announcement is aimed squarely at enterprise buyers that want tight controls over sensitive data but still need providers to watch for abuse and dangerous activity. OpenAI is arguing that it can do both: keep prompts and responses out of its hands after processing while still applying automated checks across related interactions.

In OpenAI’s words, “Zero Data Retention gives eligible API customers a clear promise: OpenAI does not retain their prompts or model responses after a request is processed. Customer content is not available to OpenAI personnel for review, and enterprise customer data is not used to train our models unless customers explicitly opt-in.” The company made clear the policy applies to eligible API customers, not broadly to consumer ChatGPT use.

That last point matters because part of OpenAI’s enterprise data posture is not new. Its developer documentation has long said that, since March 1, 2023, data sent through the OpenAI API is not used to train or improve models unless customers explicitly opt in. By default, though, OpenAI also says abuse-monitoring logs are generated and kept for up to 30 days, with eligible customers able to apply for zero data retention or modified abuse monitoring. What is new here is the public push to extend zero-retention treatment to frontier-model deployments and pair it with a named safety system designed to work across sessions.

OpenAI calls that system Private Safety Processing. According to the company, it is designed to let automated safety protections analyze related interactions without giving OpenAI personnel access to the underlying prompts or responses. OpenAI said the system can work in two configurations: with content remaining on customer-controlled infrastructure, or with content stored on OpenAI’s infrastructure but encrypted with keys controlled by the customer, which OpenAI personnel do not have. When the system detects risk, OpenAI said it would receive only “a narrowly defined signal indicating the type of activity involved,” rather than the content itself.

The company said Private Safety Processing is being tested with early customers. It added: “We plan to start rolling out Private Safety Processing, and share a technical white paper, in September.”

OpenAI also carved out an explicit exception for child sexual abuse material, or CSAM. The company said images flagged for potential CSAM will still be retained for manual review and legal reporting, including in Zero Data Retention deployments. That exception, OpenAI said, reflects legal reporting requirements that apply to frontier model providers.

The announcement gives OpenAI a clear point of contrast with Anthropic, a rival AI model developer. Anthropic said in June 2026 that it would require 30-day retention for all traffic on its Mythos-class frontier models, while saying the retained data would be used for safety and abuse purposes, not for training. OpenAI is now positioning its approach as a privacy-focused alternative for customers that do not want prompts and outputs held by the model provider at all.

OpenAI cited Glean, Databricks, Abridge and Microsoft in its post, and included a statement from Glean Chief Information Security Officer Sunil Agrawal backing the approach. For now, the immediate takeaway is narrower: OpenAI is trying to sell enterprise-grade privacy for its most advanced API offerings without abandoning safety oversight, and it says customers should get a closer look at how that works when the rollout and technical paper arrive in September.

Tags: #openai, #privacy, #enterprise, #aisafety